Dlink Dwr-111 Firmware vulnerabilities

4 known vulnerabilities affecting dlink/dwr-111_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2018-19300CRITICALCVSS 9.8≤ 1.012019-04-11
CVE-2018-19300 [CRITICAL] CWE-20 CVE-2018-19300: On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) befor
nvd
CVE-2018-10824CRITICALCVSS 9.8PoC≤ 1.012018-10-17
CVE-2018-10824 [CRITICAL] CWE-22 CVE-2018-10824: An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02 An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is stored in plaintext in the /tmp/csman/0 file. An attacker having a directory traversal (or LFI)
nvd
CVE-2018-10823HIGHCVSS 8.8ExploitedPoC≤ 1.012018-10-17
CVE-2018-10823 [HIGH] CWE-78 CVE-2018-10823: An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internal
nvd
CVE-2018-10822HIGHCVSS 7.5PoC≤ 1.012018-10-17
CVE-2018-10822 [HIGH] CVE-2018-10822: Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L thro Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /.. or // after "GET /uir" in an HTTP request. NOTE:
nvd